Link to home
Start Free TrialLog in
Avatar of Faustino-12
Faustino-12Flag for United States of America

asked on

Create a dmz on cisco851w

i need to creat a dmz on cisco851w EN PORT F0/0
NETWORK IP 176.16.10.0/24
DMZ-NAME-WEBSERVER
please need details steps and cisco commands?
* I will need to put a server on this port only.
Thanks,
Avatar of John Meggers
John Meggers
Flag of United States of America image

I would suggest you need zone-based firewall (ZBF) for this, assuming it's supported in software available for the 851W.  Without ZBF you can still create a separate VLAN for the server, but routing will treat it as any other interface.  The fact that you say "DMZ" implies to me that you want to restrict traffic in various ways. You can restrict traffic with access-lists, but the dynamic nature of traffic these days makes stateful firewalls much more appropriate.

The VLAN portion of what you need is pretty easy to do, but ZBF is not especially easy for an inexperienced user to configure.  You can take a look at http://www.cisco.com/en/US/partner/docs/ios/sec_data_plane/configuration/guide/sec_zone_polcy_firew.html for information.  At a basic level, you create policies (allow HTTP, block telnet, etc.) that get applied to zones, and link interfaces with those zones.  In your situation, you'd most likely have outside, inside and DMZ zones.  Without knowing specifics of your topology and policies, it's going to be very difficult for anyone on this site to tell you exactly what commands to configure.

If you don't have software that supports ZBF, my recommendation would be to front-end the router with an ASA 5505.
Avatar of Faustino-12

ASKER

ok so. i do not have zbf. what are the steps to configure my vlan on port f0/0
ASKER CERTIFIED SOLUTION
Avatar of John Meggers
John Meggers
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thanks